Globally enables or disables riskware detection based on the set of Trellix common rules on the EX Series appliance only.
When this command is enabled, email that matches a Trellix common riskware rule will generate an alert notification. You can view the analysis results on the eAlerts > Riskware page of the Web UI.
Note
Riskware detection based on the set of Trellix common rules is enabled by default. When it is disabled, the following warning message is displayed:
The rules are now disabled. FireEye recommends re-enabling these rules for security reasons.
Note
This command replaces the deprecated
analysis riskware policy enablecommand introduced in Release 8.0.
Syntax
[no] analysis riskware policy fe-rules enable
Parameters
no
Use the no form of this command to globally disable riskware detection based on the set of Trellix common rules on the EX Series appliance.
Example
The following example enables riskware detection based on the set of Trellix common rules on the EX Series appliance:
hostname (config) # analysis riskware policy fe-rules enable
The following example disables riskware detection for Trellix rules on the EX Series appliance:
hostname (config) # no analysis riskware policy fe-rules enable
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 8.4.1